Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Pearson CISM New Attempt

Page: 37 / 86
Total 1191 questions

Certified Information Security Manager Questions and Answers

Question 145

Which of the following BEST helps to ensure risk appetite is considered during the risk treatment process?

Options:

A.

Formalized risk management framework

B.

Organization-wide risk awareness and training programs

C.

Use of a quantitative risk measurement approach

D.

Automated monitoring of key risk indicators (KRIs)

Question 146

Which of the following is the PRIMARY role of the information security manager in application development?

Options:

A.

To ensure security is integrated into the system development life cycle (SDLC)

B.

To ensure compliance with industry best practice

C.

To ensure enterprise security controls are implemented

D.

To ensure control procedures address business risk

Question 147

Relationships between critical systems are BEST understood by

Options:

A.

evaluating key performance indicators (KPIs)

B.

performing a business impact analysis (BIA)

C.

developing a system classification scheme

D.

evaluating the recovery time objectives (RTOs)

Question 148

Which of the following is the BEST approach to reduce unnecessary duplication of compliance activities?

Options:

A.

Documentation of control procedures

B.

Standardization of compliance requirements

C.

Automation of controls

D.

Integration of assurance efforts

Page: 37 / 86
Total 1191 questions